Member of Technical Staff, Security

Anchorage

United States

On-site

USD 120,000 - 170,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Anchorage Digital is seeking a security-focused professional to build and maintain automation for vulnerability detection across code and live systems. You will conduct security assessments, perform code reviews, and guide secure development practices.

You will develop vulnerability management workflows, establish guardrails for code and cloud resources, and lead incident response activities while collaborating with Engineering, Infrastructure, and Compliance teams to improve security across the

Qualifications

  • 3+ years of hands-on experience in security engineering, appsec, pentesting, or security operations.
  • Experience building or maintaining security tools, integrations, or automation workflows using Python, Go, or similar.
  • Experience with static and dynamic analysis to identify issues in code and live systems.

Responsibilities

  • Build and maintain security automation and tooling to detect vulnerabilities through static and dynamic analysis across code and live systems.
  • Conduct security assessments, penetration tests, and code reviews to identify high-risk issues and provide secure development guidance.
  • Develop and operate vulnerability management workflows with engineering teams to prioritize and remediate findings.
  • Establish and test security guardrails for code, cloud resources, and infrastructure across the Anchorage platform.

Skills

Security engineering
AppSec
Penetration testing
Security operations
Security tooling & automation
Cloud security
Incident response
Communication
Bug bounty collaboration

Tools

Semgrep
CodeQL
Burp Suite

Job description


  • Build and maintain security automation and tooling to detect vulnerabilities through static and dynamic analysis across code and live systems.

  • Conduct application security assessments, penetration tests, and code reviews to identify high-risk security issues and provide secure development guidance.

  • Develop and operate vulnerability management workflows, partnering with engineering teams to prioritize and remediate findings.

  • Establish and test security guardrails for code, cloud resources, and infrastructure components throughout the Anchorage platform.

  • Monitor and respond to security events and configuration anomalies across the organization, leading investigation and containment efforts.

  • Manage the full vulnerability lifecycle from discovery through remediation, tracking progress and ensuring timely closure of findings.

  • Lead or substantially contribute to Security Operations initiatives with minimal oversight, coordinating across team boundaries to drive projects to completion.

  • Break complex security problems into manageable workstreams with accurate scope and time estimates. Present options clearly and provide well-reasoned priority recommendations.

  • Deliver assurance artifacts and evidence for regulated entity requirements, supporting audit and compliance efforts.

  • Balance speed of response with thoroughness of investigation, adapting approach based on risk and business impact.

  • Understand and help implement the company's security strategy by participating in planning and defining Security Operations goals in alignment with Anchorage Digital's overall objectives.

  • Stay alert to emerging threats, vulnerabilities, and industry trends that could affect organizational security posture.

  • Consider security holistically across the product ecosystem - applications, infrastructure, and third-party integrations - while fostering a security-first culture.

  • Collaborate cross-functionally with Engineering, Infrastructure, and Compliance teams to embed security into development and operational processes.

  • Share knowledge broadly across the team through documentation, runbooks, and post-incident reviews, preventing single points of failure.

  • Partner with engineering teams to explain security risks and remediation approaches, translating technical findings into actionable guidance.

  • Collaborate across teams to review security configurations, triage findings, and engage in technical discussions. Communicate insights and recommendations clearly to improve processes.

  • Demonstrate empathy by understanding others' context, priorities, and constraints - adapting communication style to maximize effectiveness with both technical and non-technical audiences.

  • Security Operations or AppSec experience: You have 3+ years of hands-on experience in security engineering, application security, penetration testing, or security operations.

  • Security tooling and automation: You have built or maintained security tools, integrations, or automation workflows using Python, Go, or similar languages.

  • Vulnerability assessment: You can identify and assess security vulnerabilities in applications, APIs, and cloud infrastructure, and effectively communicate remediation strategies.

  • Static and dynamic analysis: You have experience with tools like Semgrep, CodeQL, Burp Suite, or equivalent for identifying security issues in code and running systems.

  • Cloud security: You understand AWS security fundamentals including IAM, VPCs, security groups, and CloudTrail/logging.

  • Incident response: You can investigate security events, perform root cause analysis, and coordinate response efforts.

  • You have developed "computer science fundamentals," i.e. concurrency, algorithms, and data structures.

  • You genuinely care about code quality and operational excellence.

  • You prioritize security outcomes, end-user experience, and business value over "cool tech."

  • You self-describe as some combination of the following: creative, humble, ambitious, detail-oriented, hardworking, trustworthy, eager to learn, methodical, action-oriented, and tenacious.

  • You have experience running or participating in bug bounty programs (HackerOne, Bugcrowd, etc.).

  • You have worked in a regulated financial services, fintech, or crypto environment.

  • You have exposure to blockchain security, smart contract auditing, or Web3 technologies.

  • You have built or contributed to open-source security tools.

  • You hold relevant certifications (OSCP, GWAPT, GCIH, AWS Security Specialty, etc.).

  • You read blockchain protocol white papers for fun, and stay up to date with the proliferation of crypto-asset innovations.

  • You were emotionally moved by the soundtrack to Hamilton, which chronicles the founding of a new financial system.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Member of Technical Staff, Security
Member of Technical Staff, Security

blockchaincapital.com • United States

On-site
USD 140,000 - 210,000
Member of Technical Staff, Security Engineering
Member of Technical Staff, Security Engineering

blockchaincapital.com • United States

On-site
USD 90,000 - 130,000
Engineering Lead, Security
Engineering Lead, Security

blockchaincapital.com • United States

On-site
USD 180,000 - 240,000
Engineering Lead, Security
Engineering Lead, Security

Anchorage Digital • United States

On-site
USD 120,000 - 160,000
Application Security Architect
Application Security Architect

Alarm.com • Tysons (VA)

On-site
USD 140,000 - 210,000
Staff Platform Engineer, Security
Staff Platform Engineer, Security

Engg • Denver (CO), Long Beach (CA), San Francisco (CA)

On-site
USD 160,000 - 250,000
Senior Security Engineer
Senior Security Engineer

Mach7 Technologies • New Jersey

On-site
USD 120,000 - 190,000
Security Engineer
Security Engineer

Ether.fi • Denver (CO)

On-site
USD 120,000 - 180,000
Security Engineer, Application Security
Security Engineer, Application Security

Jobtailor • California (MO)

On-site
USD 120,000 - 180,000
Security Engineer
Security Engineer

Jobtailor • Denver (CO)

On-site
USD 140,000 - 180,000